Critical Flowise Vulnerability Enables Full Server Compromise (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Obsidian Security publishes PoC for CVE-2026-40933 in Flowise
- Custom MCP tool with stdio transport executes commands without sandbox
- Malicious chatflow import triggers RCE automatically on load
- Official patch can be bypassed; latest version still vulnerable
- Mitigation: disable stdio transport, switch to SSE
"A critical remote code execution vulnerability (CVE-2026-40933) in the open-source AI platform Flowise allows attackers to fully compromise self-hosted servers by importing a malicious workflow file. Obsidian Security published a proof-of-concept. The flaw resides in the Custom MCP tool with stdio transport, which executes commands without sandboxing. The official patch can be bypassed; the latest release remains vulnerable. Disabling stdio transport and switching to SSE is recommended."
#RCE vulnerability
#Flowise AI platform
#MCP protocol
no comments yet.